CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8630
9.4 CRITICAL

Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.

Sep 27, 2024
CVE-2024-8310
9.8 CRITICAL

OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.

Sep 27, 2024
CVE-2024-6981
9.8 CRITICAL

OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.

Sep 27, 2024
CVE-2024-46367
9.6 CRITICAL

A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within …

Sep 27, 2024
CVE-2024-47070
9.0 CRITICAL

authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header …

Sep 27, 2024
CVE-2024-8643
9.8 CRITICAL

Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking.This issue affects ValeApp: before v2.0.0.

Sep 27, 2024
CVE-2024-8607
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection.This issue affects ValeApp: before v2.0.0.

Sep 27, 2024
CVE-2024-46628
9.8 CRITICAL

Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.

Sep 26, 2024
CVE-2024-46627
9.1 CRITICAL

Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

Sep 26, 2024
CVE-2024-7108
9.8 CRITICAL

Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CyberMath: before CYBM.240816253.

Sep 26, 2024
CVE-2024-0132
9.0 CRITICAL

NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain …

Sep 26, 2024
CVE-2024-7772
9.8 CRITICAL

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in …

Sep 26, 2024
CVE-2024-6593
9.1 CRITICAL

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. This …

Sep 25, 2024
CVE-2024-6592
9.1 CRITICAL

Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on …

Sep 25, 2024
CVE-2024-8275
9.8 CRITICAL

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, …

Sep 25, 2024
CVE-2024-8514
9.1 CRITICAL

The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via …

Sep 25, 2024
CVE-2024-7385
9.1 CRITICAL

The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 …

Sep 25, 2024
CVE-2024-8621
9.9 CRITICAL

The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, …

Sep 25, 2024
CVE-2024-8485
9.8 CRITICAL

The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via …

Sep 25, 2024
CVE-2024-9148
9.6 CRITICAL

Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.

Sep 25, 2024
CVE-2024-9142
9.8 CRITICAL

External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to …

Sep 25, 2024
CVE-2024-8940
10.0 CRITICAL

Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload …

Sep 25, 2024
CVE-2024-8878
9.8 CRITICAL

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of …

Sep 25, 2024
CVE-2024-8877
9.8 CRITICAL

Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement …

Sep 25, 2024
CVE-2024-8436
9.9 CRITICAL

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions …

Sep 25, 2024
CVE-2024-46957
9.8 CRITICAL

Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in …

Sep 25, 2024
CVE-2024-46612
9.8 CRITICAL

IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.

Sep 25, 2024
CVE-2024-45066
10.0 CRITICAL

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.

Sep 25, 2024
CVE-2024-43693
10.0 CRITICAL

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.

Sep 25, 2024
CVE-2024-43692
9.8 CRITICAL

An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.

Sep 25, 2024
CVE-2024-43423
9.8 CRITICAL

The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

Sep 25, 2024
CVE-2024-42797
9.8 CRITICAL

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid …

Sep 25, 2024
CVE-2024-42507
9.8 CRITICAL

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's …

Sep 25, 2024
CVE-2024-42506
9.8 CRITICAL

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's …

Sep 25, 2024
CVE-2024-42505
9.8 CRITICAL

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's …

Sep 25, 2024
CVE-2023-26689
9.8 CRITICAL

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

Sep 25, 2024
CVE-2023-26686
9.8 CRITICAL

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.

Sep 25, 2024
CVE-2024-8791
9.8 CRITICAL

The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up …

Sep 24, 2024
CVE-2024-8671
9.1 CRITICAL

The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php …

Sep 24, 2024
CVE-2024-8624
9.9 CRITICAL

The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attribute of the 'mdf_select_title' shortcode in …

Sep 24, 2024
CVE-2024-7024
9.6 CRITICAL

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Sep 23, 2024
CVE-2024-47222
9.8 CRITICAL

New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.

Sep 23, 2024
CVE-2024-0005
9.1 CRITICAL

A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.

Sep 23, 2024
CVE-2024-0004
9.1 CRITICAL

A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.

Sep 23, 2024
CVE-2024-0003
9.1 CRITICAL

A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged …

Sep 23, 2024
CVE-2024-0002
10.0 CRITICAL

A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.

Sep 23, 2024
CVE-2024-0001
10.0 CRITICAL

A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated …

Sep 23, 2024
CVE-2024-9014
9.9 CRITICAL

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID …

Sep 23, 2024
CVE-2024-47066
9.0 CRITICAL

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and …

Sep 23, 2024
CVE-2024-46997
9.8 CRITICAL

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed …

Sep 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.